![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello everybody,
My first post and here I am asking for help Could you please assist with removing the above from my PC. I have attached the logs requested in the general instructions thread. thanks |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
thanks for the quick reply
new log uploaded |
|
#4
|
||||
|
||||
|
Java(TM) 6 Update 29 <--- uninstall outdated java.
Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6 NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Attached is fixlist.txt
Now re-enter System Recovery Options. Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (How to attach) Now attempt to boot normally. Download and run OTM. Download OTM by Old Timer and save it to your Desktop.
Code:
:Files C:\Windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\gac_64\desktop.ini C:\Windows\system32\consrv.dll C:\Windows\8455191.exe C:\Windows\8455191.dat C:\Windows\system32\CE3.dll :Commands [emptytemp] [Reboot]
NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post. Run FRST again like you did the first time and attach the log. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
done all the steps
here are the logs (the fixlog from FRST, the results log from OTM, the FRST scan log and the MGlogs.zip) I will let you know shortly if the infection is gone. much appreciated |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
no luck
![]() it's still detected by Comodo and by Emisoft Anti Malware I don't see any symptoms but I am afraid for my passwords and various accounts |
|
#7
|
||||
|
||||
|
Logs did not attach!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
|||
|
|||
|
...sorry
|
|
#9
|
||||
|
||||
|
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Attached is fixlist.txt
Now re-enter System Recovery Options. Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (How to attach) Now attempt to boot normally. Download Combofix to your desktop. Do not run it by double clicking! See below. Now we need to use ComboFix by sUBs
Code:
KILLALL:: File:: C:\Windows\System32\CE3.dll C:\Windows\304576.dat C:\Windows\304576.exe C:\Windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\gac_64\desktop.ini
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
|||
|
|||
|
sorry for the late reply. I was away with work
done. attaching logs... I think we succeeded as it wasn't detected in these past few minutes. will report back in a short while to confirm. did I see correctly that some windows updates were uninstalled by combofix, or did I misread something? |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Run FRST again like you did in post # 2 please and atach the log. Also describe how things are running. No, I don't think CF took out windows updates...
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#12
|
|||
|
|||
|
log attached
everything looks good, working properly. it's not detected anymore ![]() you guys, and especially you Kestrel13!, are the best ![]() many thanks |
|
#13
|
||||
|
||||
|
Thankyou! I am glad everything is running normally again.
![]() If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| c:\Windows\assembly\GAC_32\Desktop.ini | Gemini II | Malware Removal | 13 | 06-08-12 06:41 |
| GAC_32/GAC_64 desktop.ini help | thepspgamer | Malware Removal | 38 | 05-29-12 15:46 |
| Help, I have zeroaccess rootkit / GAC_32 desktop.ini virus | masumane | Malware Removal | 4 | 05-26-12 12:55 |
| Removing GAC_32 and 64\Desktop.ini | dislocatedkarma | Malware Removal | 16 | 05-24-12 21:08 |
| (c:\Windows\assembly\GAC_32\Desktop.ini) Keeps me off Internet: Partially Removed? | talent4theworld | Malware Removal | 22 | 02-09-12 14:54 |